Anthropic reported detecting “industrial-scale” distillation activity targeting its Claude models and attributed it to three Chinese AI labs: DeepSeek, Moonshot, and MiniMax. Anthropic said the actors used ~24,000 fraudulent accounts and generated ~16 million exchanges with Claude, allegedly leveraging proxy/reseller access to evade controls and violate terms of service and regional restrictions. The company characterized the activity as deliberate capability extraction rather than normal customer usage, and paired the disclosure with renewed calls for stronger export controls.
Anthropic warned that models produced via illicit distillation may lack safety guardrails and could be repurposed for national security-relevant misuse, including offensive cyber operations, surveillance, and disinformation. Reporting described tactics including coordinated fake-account networks (“hydra clusters”), proxy services, and prompt patterns aimed at extracting advanced reasoning and other capabilities at scale; one breakdown cited DeepSeek activity at 150,000+ exchanges and Moonshot at 3.4M+ exchanges, alongside prompt engineering intended to elicit step-by-step reasoning. Separate coverage on training-data memorization/copyright and a vendor blog on AI-driven crypto fraud discuss broader AI risk trends but do not address Anthropic’s specific distillation allegations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In response to the detected activity, Anthropic said it is deploying classifiers and behavioral fingerprinting, tightening account verification, and adding safeguards to reduce the usefulness of outputs for illicit distillation. The company also said it is sharing technical indicators with other AI labs, cloud providers, authorities, and policymakers while urging stronger export controls.
Anthropic publicly attributed the campaigns with high confidence using IP correlations, request metadata, infrastructure indicators, and partner corroboration. It said the activity involved roughly 24,000 fraudulent accounts and more than 16 million exchanges focused on capabilities such as reasoning, coding, tool use, and chain-of-thought elicitation.
Anthropic said it identified separate industrial-scale efforts by DeepSeek, Moonshot AI, and MiniMax to extract Claude model capabilities through bulk querying. The campaigns used fraudulent accounts, proxy services, and "hydra cluster" account networks to evade controls and regional access restrictions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
lawfaremedia.org
Open sourcescworld.com
Open sourcehackread.com
Open sourcethehackernews.com
Open sourcebankinfosecurity.com
Open sourcetomshardware.com
Open sourcecyberscoop.com
Open sourcecybersecuritynews.com
Open sourceanthropic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.